Code between the Lines: Semantic Analysis of Android Applications

Johannes Feichtner*, Stefan Gruber

*Korrespondierende/r Autor/-in für diese Arbeit

Publikation: Beitrag in Buch/Bericht/KonferenzbandBeitrag in einem KonferenzbandBegutachtung

Abstract

Static and dynamic program analysis are the key concepts researchers apply to uncover security-critical implementation weaknesses in Android applications. As it is often not obvious in which context problematic statements occur, it is challenging to assess their practical impact. While some flaws may turn out to be bad practice but not undermine the overall security level, others could have a serious impact. Distinguishing them requires knowledge of the designated app purpose.

In this paper, we introduce a machine learning-based system that is capable of generating natural language text describing the purpose and core functionality of Android apps based on their actual code. We design a dense neural network that captures the semantic relationships of resource identifiers, string constants, and API calls contained in apps to derive a high-level picture of implemented program behavior. For arbitrary applications, our system can predict precise, human-readable keywords and short phrases that indicate the main use-cases apps are designed for.

We evaluate our solution on 67,040 real-world apps and find that with a precision between 69% and 84% we can identify keywords that also occur in the developer-provided description in Google Play. To avoid incomprehensible black box predictions, we apply a model explaining algorithm and demonstrate that our technique can substantially augment inspections of Android apps by contributing contextual information.
Originalspracheenglisch
TitelICT Systems Security and Privacy Protection - 35th IFIP TC 11 International Conference, SEC 2020, Proceedings
Redakteure/-innenMarko Hölbl, Tatjana Welzer, Kai Rannenberg
ErscheinungsortCham
Herausgeber (Verlag)Springer International Publishing AG
Seiten171-186
Seitenumfang16
Band580
ISBN (elektronisch)978-3-030-58201-2
ISBN (Print)978-3-030-58200-5
DOIs
PublikationsstatusVeröffentlicht - Sept. 2020
Veranstaltung35th International Conference on ICT Systems Security and Privacy Protection - Maribor, Slowenien
Dauer: 21 Sept. 202023 Sept. 2020
https://sec2020.um.si

Publikationsreihe

NameIFIP Advances in Information and Communication Technology
Band580 IFIP
ISSN (Print)1868-4238
ISSN (elektronisch)1868-422X

Konferenz

Konferenz35th International Conference on ICT Systems Security and Privacy Protection
KurztitelIFIP SEC 2020
Land/GebietSlowenien
OrtMaribor
Zeitraum21/09/2023/09/20
Internetadresse

ASJC Scopus subject areas

  • Informationssysteme und -management
  • Information systems
  • Computernetzwerke und -kommunikation

Fingerprint

Untersuchen Sie die Forschungsthemen von „Code between the Lines: Semantic Analysis of Android Applications“. Zusammen bilden sie einen einzigartigen Fingerprint.
  • A-SIT - Zentrum für sichere Informationstechnologie Austria

    Stranacher, K., Dominikus, S., Leitold, H., Marsalek, A., Teufl, P., Bauer, W., Aigner, M. J., Rössler, T., Neuherz, E., Dietrich, K., Zefferer, T., Mangard, S., Payer, U., Orthacker, C., Lipp, P., Reiter, A., Knall, T., Bratko, H., Bonato, M., Suzic, B., Zwattendorfer, B., Kreuzhuber, S., Oswald, M. E., Tauber, A., Posch, R., Bratko, D., Feichtner, J., Ivkovic, M., Reimair, F., Wolkerstorfer, J. & Scheibelhofer, K.

    21/05/996/08/20

    Projekt: Arbeitsgebiet

Dieses zitieren